oasis-tcs / openc2-apsc-stateless-packet-filter

OASIS OpenC2 TC: A GitHub repository is to provide configuration management and to aid in the development of the first generation OpenC2 firewall profile
https://github.com/oasis-tcs/openc2-apsc-stateless-packet-filter
Other
6 stars 10 forks source link

Comment #134

Closed alevere closed 3 years ago

alevere commented 4 years ago

For Issue #115

alevere commented 3 years ago

We reviewed common devices that perform these functions and description was the most common field. The word note was included in the definition.

Vasileios-Mavroeidis commented 3 years ago

I would change the description to "A note to annotate or provide information regarding the rule"

We should not specify if it is a human agent or not. Even though traditionally a description gives more information to a human, nowadays we can use those descriptions multipurposely. For example, we can use NLP to parse the descirptions and classify the rules that we have submitted. For example, we classify automatically rules that block trickbot C2. :)